Trao đổi với tôi

http://www.buidao.com
Showing posts with label [Source]. Show all posts
Showing posts with label [Source]. Show all posts

12/19/10

[Source] Tools and proof-of-concept codes

DISCLAIMER: All the tools in this section should be considered as proof-of-concepts tools. They are provided with the hope that they might be useful for other researches. They are not intended to be used by 'end users'. There is no support. Keep in mind that some of these tools may crash your system without a single warning! USE AT YOUR OWN RISK!

The Blue Pill Project

I wrote the original Blue Pill proof of concept code while working for COSEINC back in 2006, and presented it at the Black Hat Briefings 2006 in Las Vegas on August 3rd. In April 2007 I decided to quit COSEINC and start my own security consulting firm, Invisible Things Lab. In May 2007 Alexander Tereshkin, a former member of COSEINC AML, joined ITL as a principal researcher. Together with Alex we decided to redesign and write from scratch the New Blue Pill rootkit, so that it would be possible to use it for further research and for educational purposes. Most of the New Blue Pill’s code was developed by Alexander Tereshkin. You can get the sources from the project's website.

System Virginity Verifier

The idea behind SVV is to check important Windows System components, which are usually altered by various stealth malware, in order to ensure system integrity and to discovery potential system compromise.

See my HITB and Black Hat presentations (links below) for more details about design and usage.

modGREPER

modGREPER is a hidden module detector for Windows 2000/XP/2003. It searches through kernel memory in order to find structures which looks like a valid module description objects.

FLISTER proof-of-concept

FLISTER is a proof-of-concept code for detecting files hidden by both usermode and kernelmode Windows rootkits. It exploits the bugs (usually made by rootkit authors) in handling ZwQueryDirectoryFile() calls with ReturnSingleEntry set to TRUE. flister works on Windows 2000, XP and 2003.

NUSHU - passive covert channel engine for Linux 2.4 kernels

NUSHU is the sample implementation of TCP ISN based passive covert channel for Linux kernels, which I presented at 21st CCC in Berlin in 2004. It should be considered as proof-of-concept code, since it is only the communication channel engine.

4/25/10

[Source] HyperDbg

This image has been resized. Click this bar to view the full image. The original image is sized 1024x745.


Quote:
HyperDbg is a kernel debugger that leverages hardware-assisted virtualization. More precisely, HyperDbg is based on a minimalistic hypervisor that is installed while the system runs. Compared to traditional kernel debuggers (e.g., WinDbg, SoftIce, Rasta R0 Debugger) HyperDbg is completely transparent to the kernel and can be used to debug kernel code without the need of serial (or USB) cables. For example, HyperDbg allows to single step the execution of the kernel, even when the kernel is executing exception and interrupt handlers. Compared to traditional virtual machine based debuggers (e.g., the VMware builtin debugger), HyperDbg does not require the kernel to be run as a guest of a virtual machine, although it is as powerful.
Quote:
http://security.dico.unimi.it/hyperdbg/releases/hyperdbg_20100325.zip


More information

http://security.dico.unimi.it/hyperdbg/

4/5/10

[Source] tinyPEiD

Tên sản phẩm : tinyPEiD
Tác giả :
DungCoi + MeoConLongVang

Chân thành cảm ơn : anh T4mQu0c , khanhduy301 , anh FireDragon , anh Benina , anh TQN , anh NhatPhuongLe, anh HaiPT, anh Pete ...

Ngôn ngữ : VB6
Hình thức công bố : Open Source
Mọi hình thức sử dụng một phần hay toàn bộ code yêu cầu phải có sự đồng ý của tác giả

Làm gì ?
Đây là một tool nhỏ để scan nhận ra file được pack bằng công cụ nào. Tóm lại là tương tự PEiD (Nên mình để cái tên tinyPEiD luôn cho dễ hiểu).

Cấu trúc base file như sau :
Quote:
; Made with Add Signature v2.00 by BoB / BobSoft ..
; 4445 Signatures in list ..

[!EP (ExE Pack) V1.0 -> Elite Coding Group]
signature = 60 68 ?? ?? ?? ?? B8 ?? ?? ?? ?? FF 10
ep_only = true

[!EP (ExE Pack) V1.0 -> Elite Coding Group]
signature = 25 ?? ?? ?? ?? 61 87 CC 55 45 45 55 81 ED CA 00 00 00 55 A4 B3 02 FF 14 24 73 F8 33 C9 FF 14 24 73 18 33 C0 FF 14 24 73 1F B3 02 41 B0 10 FF 14 24 12 C0 73 F9 75 3C AA EB DC FF 54 24 04 2B CB 75 0F FF 54 24 08 EB 27 AC D1 E8 74 30 13 C9 EB 1B 91 48 C1 E0 08 AC FF 54 24 08 3D 00 7D 00 00 73 0A 80 FC 05 73 06 83 F8 7F 77 02 41 41 95 8B C5 B3 01 56 8B F7 2B F0 F3 A4 5E EB 99 BD ?? ?? ?? ?? FF 65 28
ep_only = true
Như các bạn thấy là bợ nguyên các userdb của PEiD luôn
Hiện mình sài ké của PEiD và chưa có ý định tự làm

Bạn có thể kéo thả file muốn scan vào TextBox (Hoặc nhập bằng tay đường dẫn) rồi tiến hành scan

Mình có viết hàm để scan cả 2 trường hợp :
Quote:
ep_only = true
ep_only = false
Nhưng mà phần xử lý với fasle (Scan nguyên file) chậm quá nên mình tạm vứt đi

Hiện không biết sao chứ cái userdb mình dùng scan trùng hơi bị nhiều (Không biết do cái db có vấn đề hay code mình có vấn đề nữa)

Tốc độ scan thì hơi chậm

Hình ảnh demo :



Pass : vvn


Về việc Avira báo nhầm mình đã report, kết quả nè


Cập nhật :
1. Đưa thẳng DB lên bộ nhớ scan cho lẹ
2. Do bây giờ scan lẹ lắm nên khi kéo file vào thì mình scan tại chỗ luôn, bỏ nút Scan đi cho đỡ phiền
3. Thay đổi cách truy xuất DB cho chính xác hơn cách cũ (Cách cũ sẽ truy xuất 1 số DB nhầm)
4. Xóa bớt vài sign Yoda làm scan trật miết.

Demo :


Trong thư mục tải về có chứa sẵn 1 file thực thi (.exe) để bạn tiện test nếu không có sẵn VB6.

Thao tác sử dụng là kéo thẳng từ explorer file muốn kiểm tra vào TextBox đường dẫn.


Pass giải nén : vvn

Dowload:
http://www.mediafire.com/?nkyy2mmtmnm

reflink: http://virusvn.com/forum/showthread.php?t=1846

3/7/10

[Source] vnCrypt

Cái này là đề tài môn.
Post lên đây cho anh em
Còn có nhiều vấn đề nhưng tạm thời thế này đã

Giới thiệu :
Phần mềm vnCrypt kết hợp các hàm mã hóa có sẵn của Windows, kết hợp với thuật toán lấy giá trị băm mảng MD5 để mã hóa và bảo vệ tính bảo toàn của khối dữ liệu
Phần mềm giải quyết được 3 mục tiêu :
- Không thể tìm ra mật khẩu ban đầu trong một khoảng thời gian chấp nhận được (Khi sử dụng BruteForce)
- Kiểm tra để luôn bảo đảm tính bảo toàn trước và sau khi mã hóa. Tự nhận ra và cảnh báo với bất kỳ sự thay đổi nào lên khối dữ liệu bị mã hóa (Nhất định thôi nhé )
- Có thể xử lý khối dữ liệu ở mọi kích thước.

Mô tả cấu trúc :


Hình ảnh chương trình :




Note : Chương trình có dùng control của bạn Dương Quốc Hưng bên VBClub
Đính kèm là source của chương trình

http://www.mediafire.com/?ymkr2kdwimc

2/24/10

[Source] dnscat - DNS Backdoors

- Khá giống Netcat (nc.exe) hay Ncat về mặt ý tưởng.
- dnscat sử dụng giao thức DNS để truyền dữ liệu vì thế có thể qua mặt được hầu hết các loài firewall.


Thông tin chi tiết tại đây:
http://www.skullsecurity.org/wiki/index.php/Dnscat
Download tại đây:
http://www.skullsecurity.org/wiki/in...tool#Downloads

Reflink: http://virusvn.com/forum/showthread.php?p=13186#post13186

1/20/10

[Source] :[diStorm64}:

diStorm64 is a professional quality open source disassembler library for AMD64, licensed under the BSD license.

diStorm is a binary stream disassembler. It's capable of disassembling 80x86 instructions in 64 bits (AMD64, X86-64) and both in 16 and 32 bits. In addition, it disassembles FPU, MMX, SSE, SSE2, SSE3, SSSE3, SSE4, 3DNow! (w/ extensions), new x86-64 instruction sets, VMX, and AMD's SVM! diStorm was written to decode quickly every instruction as accurately as possible. Robust decoding, while taking special care for valid or unused prefixes, is what makes this disassembler powerful, especially for research. Another benefit that might come in handy is that the module was written as multi-threaded, which means you could disassemble several streams or more simultaneously.
For rapidly use, diStorm is compiled for Python and is easily used in C as well. diStorm was originally written under Windows and ported later to Linux and Mac. The source code is portable and platform independent (supports both little and big endianity).
It also can be used as a ring0 disassembler (tested as a kernel driver using the DDK under Windows)!

Link: http://www.ragestorm.net/distorm/
Download the package now:

1/15/10

[Source] Delphi. innounp, the Inno Setup Unpacker

innounp, the Inno Setup Unpacker
Version 0.28

Supports Inno Setup versions 2.0.11 through 5.3.7

Download: http://sourceforge.net/projects/innounp/files/


Inno Setup is a popular program for making software installations. Unfortunately, there is no official unpacker - the only method of getting the files out of the self-extracting executable is to run it. One piece of software that addresses this issue is Sergei Wanin's InstallExplorer, a plug-in for the FAR Manager that unpacks several types of installations, including Inno Setup (IS). But since it is not updated in a timely fashion, and so does not support the latest IS most of the time, this program was born. The advantages over InstallExplorer are:

  • Innounp is open source and based on IS source. Therefore, it is more likely to support future IS versions.
  • It recovers portions of the installation script (.iss file), including the registry changes and the compiled Innerfuse/RemObjects Pascal Script, if available.

If you want to report a bug, request a feature, or discuss anything else related to the program, please write to the forum.

RefLink: http://innounp.sourceforge.net/

[Source] Delphi. Malzilla exploring malicious pages

This was my description of Malzilla: Malware hunting tool

Others think that Malzilla deserves some better description.

Home page: http://malzilla.sourceforge.net/index.html

JohnC from Malware Domain List says:
"Web pages that contain exploits often use a series of redirects and obfuscated code to make it more difficult for somebody to follow. MalZilla is a useful program for use in exploring malicious pages. It allows you to choose your own user agent and referrer, and has the ability to use proxies. It shows you the full source of webpages and all the HTTP headers. It gives you various decoders to try and deobfuscate javascript aswell."

Softpedia says:
"Explore malicious webpages and view their code with Malzilla"

Valentin from Chip Online says:
"Malware-Jäger aufgepasst: Ein neues Tool mit dem Namen Malzilla nimmt verschlüsselten Javascripts den Schrecken."

Dowload:

Malzilla:
Latest binaries for Windows can be downloaded from here.
Source code can be downloaded from here.

Malzilla add-ons:
Templates Pack01 - navigator


Misc tools:
PDF_streams_inflater - find and extract zlib compressed streams from PDF files
XORer - XOR a file
InnoBF - brute force password-protected InnoSetup-based installers (sources)

[Source] VB.Breakthrough !! UPDATED - Completely hiding a process from the task manager in 9x and NT!

This is really a great breakthrough, this is how to completely and truely hide a process from being listed in the task manager's process list (or *any* other program that lists currently running processes!). It is done in a completely different way (it uses a kernel mode driver!) You gotta see that, people! It will completely change the way people look at windows NT/XP. I've seen many other submissions on how to hide a process, but none of them truely hides the process, instead, they simply either clear the list of Task Manager's Process List or simply disable the task manager. But this submission is completely different. Hope you guys like it, and if you do, please vote for me. :D ------------------------------------------------------------------ [9:02 AM 9/13/2006] Added ShowProcess function! ------------------------------------------------------------------ [4:12 PM 9/13/2006] Some minor changes ------------------------------------------------------------------ [8:03 PM 10/28/2006] (Final I) 1- Packed the project into a ActiveX DLL file that includes all needed .sys files. 2- Added some useful functions: GetProcessByName() and others!

Download code

RefLink: http://www.planet-source-code.com/vb/scripts/ShowCode.asp?lngWId=1&txtCodeId=66529

[Source] VC. Chương trình soạn thảo văn bản bằng C | TextEditor - Pure Win32API

Đây là chương trình xem, sửa file text (ANSI) viết bằng win32API chính thức của mình chia sẻ với mọi người sau gần một tháng vật lộn với win32API, cũng như lỗi về con trỏ, cấp phát động.
Đây là ảnh chụp

So với NotePad của windows, chương trình tất nhiên vẫn còn mặt chưa được, nhưng mình đã tốn khá nhiều thời gian cho nó, nên không muốn phải lúi húi sửa thêm nữa mà để mọi người góp ý. Trong đường dẫn tải dưới đây có cả mã nguồn và file chạy.)
http://www.mediafire.com/?hwywxdwdot2
Cái có khác so với notePad là việc mình thêm vào đó thanh công cụ và thêm chức năng bôi đen trước khi tìm kiếm trên văn bản (bấm Ctr+F hay Ctr+H) đoạn bôi đen được ghi nhớ ngay trong hộp thoại tìm kiếm.
Sau lần lập trình này chắc mình phải chuyển sang MFC ngay.

RefLink: http://forums.congdongcviet.com/showthread.php?t=17739

[Source] C# Process Hacker

Introduction

Process Hacker is a feature-packed tool for manipulating processes and services on your computer.

Key features of Process Hacker:

  • A simple, customizable tree view with highlighting showing you the processes running on your computer.
    Process Hacker
  • Detailed performance graphs.
    Graphs
  • A complete list of services and full control over them (start, stop, pause, resume and delete).
  • A list of network connections.
  • Comprehensive information for all processes: full process performance history, thread listing and stacks with dbghelp symbols, token information, module and mapped file information, virtual memory map, environment variables, handles, ...
  • Full control over all processes, even processes protected by rootkits or security software. Its kernel-mode driver has unique abilities which allows it to terminate, suspend and resume all processes and threads, including software like IceSword, avast! anti-virus, AVG Antivirus, COMODO Internet Security, etc. (just to name a few).
    Terminating IceSword
  • Find hidden processes and terminate them. Process Hacker detects processes hidden by simple rootkits such as Hacker Defender and FU.
    Hacker Defender detection
  • Easy DLL injection and unloading - simply right-click a process and select "Inject DLL" to inject and right-click a module and select "Unload" to unload!
  • Many more features...

System Requirements

  • .NET Framework 2.0
  • Microsoft Windows XP SP2 or above, 32-bit or 64-bit. Please note that certain functionality including detection of hidden processes, full control over all processes and the ability to protect/unprotect processes is only available on 32-bit systems.